← Back to CVE Registry
CVE-2026-129688.8high[patched]
Unauthenticated Stored XSS via Arbitrary SVG Upload
TARGET ECOSYSTEM / VENDORProduct Addons
AFFECTED PRODUCTProduct Addons – WowAddons (< 1.6.15)
CWE CLASSIFICATIONCWE-79: Cross-Site Scripting
PUBLISHED DATE2026-07-01
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
Product Addons – WowAddons (< 1.6.15) does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline. This allows an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
Impact
- Impact: Unauthenticated Stored XSS leading to admin session takeover.
- Fixed Version: 1.6.15
- CVSS Score: 8.8 (High)